Sr. Security Analyst - IAM

Burlingame, California

Applications have closed
About Lyra HealthLyra is transforming mental health care through technology with a human touch to help people feel emotionally healthy at work and at home. We work with industry leaders, such as Morgan Stanley, Uber, Amgen, and other Fortune 500 companies, to improve access to effective, high-quality mental health care for their employees and their families. With our innovative digital care platform and global provider network, 10 million people can receive the best care and feel better, faster. Founded by David Ebersman, former CFO of Facebook and Genentech, Lyra has raised more than $900 million.
About the RoleProtecting our users' privacy and securing our data is critical to us at Lyra Health. This is a lead operational role supporting identity lifecycle management and identity governance and administration. The ideal candidate will be able to self-organize and work cross-functionally (with legal, product, engineering, data, clinical, and other business teams) to lead business efforts while enabling appropriate access levels. This role reports to the Head of Security.
This role can be full-time in our Burlingame, CA headquarters, OR virtual (remote candidates must be based in the United States).


  • Provide users with appropriate, role-based access and services in accordance with industry standard Identity and Access Management (IAM) principles
  • Control permissions for who can access what information, working on a default basis of least-privilege and zero-trust
  • Process system access requests for a variety of business and technology applications, per internal procedure/policy and SLAs, furthering Lyra’s identity lifecycle management
  • Leverage various IAM technologies (such as Okta, other ID/SaaS management tools) to verify necessity and scope of individual or group access 
  • Act as a leader within the Security organization to support fellow members and actively contribute to the growth and development of the security team
  • Develop and drive IAM strategy 
  • Analyze and improve operational effectiveness as well as defining and upholding program objectives and access control standards 
  • Active identification and management of internal and external IAM risks and opportunities for improvement
  • Serve as SME for IAM related controls and activities, including audit support


  • At least 8 years of relevant professional experience working within an organization in the areas of security, privacy, data protection and/or data governance
  • Knowledge of the principles, practices and techniques of security and access control
  • Proficiency in IAM technologies/solutions, such as identity governance, privileged access management, single sign-on, multi-factor authentication and how they integrate with other IT functions
  • Functional abilities in SQL and database level access
  • Excellent, effective communication skills (both written and oral)
  • Bachelor's degree in a related field, or equivalent experience with relevant industry certification (CISSP, Sec+, GSEC, or other comparable certificates)
  • Strong understanding of security domains outside of access control, such as Incident Response, BC/DR, network security design and architecture, endpoint protection, SSO, vulnerability management, intrusion detection, risk management, data loss prevention, and forensics. 

Preferred Qualifications

  • Working knowledge of Amazon Web Services and knowledge of cloud security concepts
  • Past contributions to developing Information Technology and Information Security policies and controls in a regulated environment – Health Information Trust Alliance (HiTrust), SOC 2, ISO, SOX, and experience with other frameworks

Diversity & Inclusion at Lyra

  • Diversity, equity, inclusion, and belonging (DEIB) at Lyra is essential to the way we deliver culturally responsive care, build and manage our provider network, and support holistic efforts to strengthen DEIB in workplaces around the world—including our own.
  • People come to Lyra with a range of needs, backgrounds, and abilities that influence their response to mental health support. Our diverse network of providers delivers comprehensive mental health treatment and support rooted in culturally responsive care, a multicultural approach that accounts for the impact of cultural backgrounds on each person’s care experience. Learn more at
We are an Equal Opportunity Employer. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, age (40 or older), disability,  genetic information or any other category protected by law.

* Salary range is an estimate based on our salary survey 💰

Tags: CISSP Cloud Forensics Governance GSEC HITRUST IAM Incident response Intrusion detection Network security Privacy Risk management SaaS SLAs SOC SOC 2 SQL SSO Strategy Vulnerability management

Perks/benefits: Career development

Regions: Remote/Anywhere North America
Country: United States
Job stats:  19  2  0
Categories: Analyst Jobs IAM Jobs

More jobs like this

Explore more InfoSec/Cybersecurity career opportunities

Find open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Analysis, Cryptography, Digital Forensics and Cyber Security in general, filtered by job title or popular skill, toolset and products used.